← All services
Penetration testing service
Secure Code Review
Manual review of the source, following the data from entry point to sink. Finds the classes of flaw that black-box testing structurally cannot reach.
What the test covers
- Authentication and authorisation implementation
- Input handling and output encoding across all trust boundaries
- Cryptographic implementation and key handling
- Secrets in source and in build configuration
- Dependency review for known-vulnerable components
- Business logic paths that are not reachable from the interface
Deliverables
- Executive summary
- Findings referenced to file and line, with the vulnerable path traced
- Prioritised remediation roadmap
- One retest round against the fixes
Out of scope
- Code quality and performance review
- Full automated SAST licensing